Legal — subprocessors
Subprocessor List
Version 1.0 · Last updated September 6, 2026 · Owner: Cyphra
In brief
This document lists the categories of subprocessors engaged by Cyphra LLC to deliver the Platform, the data each category may touch, and how we notify you of changes. It is incorporated into our Data Processing Addendum ("DPA").
1. How this list works
We organize subprocessors by category rather than naming every vendor, so this list stays accurate as vendors change. Where a specific provider is relevant, it is named below. Each entry states the category, purpose, data touched, and where our infrastructure and providers sit. Specific vendor-level details are available on request to [email protected].
Our Platform infrastructure is owned and operated by us in the United States. Our customer-facing surfaces are delivered through a global CDN/security edge, checkout is handled by a third-party payment gateway, and model inference under Cyphra-provided model access is routed through OpenRouter and the upstream model providers accessible through it.
2. Subprocessor categories
2.1 Cloud infrastructure
- Provider: Cyphra LLC (self-operated infrastructure).
- Purpose: hosting and operating the Agent Instances, storage, backups, and networking in the the United States region.
- Data touched: Customer Content, account data, logs, and backups.
- Location: the United States.
2.2 CDN and security edge
- Provider: Cloudflare, Inc.
- Purpose: content delivery, DDoS protection, TLS termination, and web application firewalling for the Web Interface, Control Panel, and Billing Portal.
- Data touched: data in transit (request metadata, IP addresses, TLS-encrypted content; content is generally not decrypted by the edge where end-to-end TLS is preserved).
- Location: global edge network, including points of presence in the EEA and UK for traffic originating there.
2.3 Payment gateway
- Provider: Stripe, Inc. and its affiliates.
- Purpose: card and alternative payment processing for orders, subscriptions, and invoices through the Billing Portal. Checkout is gateway-hosted; Cyphra never stores card numbers.
- Data touched: billing metadata (name, email, plan, invoice records); payment card data is handled exclusively by the gateway and never enters Cyphra systems.
- Location: primarily the United States; the gateway may process internationally under its own compliance program.
2.4 Model inference providers
- Providers: OpenRouter and the upstream model providers accessible through it (including OpenAI, Anthropic, Google, and Z.AI). Inference traffic under Cyphra-provided model access is routed through OpenRouter, which forwards requests to the upstream model provider selected for the request.
- Purpose: when you use Cyphra-provided model access, inference requests are routed to upstream model providers to generate responses.
- Data touched: prompts and outputs submitted under Cyphra-provided model access, plus routing metadata. Providers process such data under their own terms; see our AI & Model Provider Disclosures for what each provider does with prompts and outputs.
- Location: primarily the United States; some upstream providers may process elsewhere. Where an upstream provider processes EEA or UK personal data outside the EEA or UK, an appropriate transfer safeguard applies as described in Section 4.3 of the DPA.
- Note: this category applies only where you use Cyphra-provided model access.
2.5 Email and delivery
- Purpose: transactional email (account verification, invoices, maintenance and incident notices, password resets).
- Data touched: email addresses, names, and message content for transactional mail.
- Location: United States.
2.6 Monitoring and observability
- Purpose: uptime monitoring, metrics, error tracking, and alerting for the Platform.
- Data touched: operational logs, performance metrics, IP addresses, and error data. We configure monitoring to avoid capturing Customer Content wherever practicable.
- Location: United States.
3. BYOK is not a subprocessor relationship
If you supply your own model provider API keys ("BYOK"), the model providers you choose are your direct providers, not our subprocessors. We do not select them, route to them, or contract with them for you: requests go directly from your Agent Instance to the provider you chose using your key. Your keys are encrypted at rest, never logged, and remain your property. You are responsible for the provider's terms, its data handling, and provider-side usage and quota. You may review your provider's policies directly; the model providers we route to under Cyphra-provided model access are the only inference subprocessors listed in Section 2.4.
4. Open-source components (not subprocessors)
The Platform is built in part on open-source software operating within our own infrastructure — for example, the chat frontend used for the Web Interface experience, the instance management layer behind the Control Panel, and the billing system behind the Billing Portal. These components run on our infrastructure under our control; they are software, not third-party data processors, and they are not subprocessors. They are acknowledged and licensed under our Open Source Notices document. Third-party names appear in that document only where a component's license requires attribution.
5. Change notification
We update this list when we add, remove, or materially change a subprocessor. For new subprocessors or material role changes, we give advance notice as described in Section 4.2 of the DPA — at least 30 days before engagement — by updating this list and, for material additions, by email to the account's registered contact. You have the objection rights set out in the DPA.
6. Contact
Subprocessor and data protection questions: [email protected]. General support: [email protected].
7. Version history
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | September 6, 2026 | Initial publication. |
| 1.1 | September 15, 2026 | Updated surface descriptions: browser-based Web Interface on desktop and mobile; no companion mobile app. |
